1. Our Core Ethical Principles Regarding Data Protection
The Association des Amis de la Conservation et de la Restauration de la Chapelle Notre Dame de Montgauzy (RNA W091002479, SIREN 890439664) attaches fundamental value to the fundamental human rights of privacy, data protection, and individual confidentiality.
As a civic, non-profit organization dedicated exclusively to cultural heritage conservation in Foix and the Ariège department, we reject the surveillance capitalism and invasive profiling that characterize the modern commercial web. We do not monetize personal data, we do not partner with data brokers, we deploy zero commercial advertising trackers, and we will never sell, rent, or trade your contact information to any commercial enterprise.
Data Controller Identification
Entity: Association des Amis de la Chapelle Notre Dame de Montgauzy
Headquarters: 26 B RUE SAINT-VINCENT, 09000 FOIX, FRANCE
Data Protection Contact: Laurent Fabre, Secretary General & Privacy Delegate
Dedicated Contact Email: [email protected]
2. Categories of Personal Data Collected & Lawful Bases for Processing
In accordance with the principle of data minimization (Article 5-1-c of the GDPR), we collect only the strictly necessary data elements required to process civic inquiries, register volunteers for fieldwork insurance, and administer statutory membership records.
A. Contact & Inquiry Correspondence
Data Processed: Full name, electronic mail address, telephone number (optional), message subject, and inquiry narrative.
Lawful Basis (Article 6-1-b / 6-1-f): Legitimate interest of the association in responding to civic correspondence, historical inquiries, and event reservations.
Retention Period: Kept only for the duration necessary to address your inquiry, and deleted after 12 months of inactivity.
B. Statutory Membership & Volunteer Rosters
Data Processed: Full name, postal address in Ariège or elsewhere, email, telephone number, emergency contact (for fieldwork), and membership dues payment records.
Lawful Basis (Article 6-1-b / 6-1-c): Contractual necessity to administer statutory membership under the French Law of 1901 and legal obligation to maintain certified volunteer rosters for group civil liability insurance.
Retention Period: Maintained during active membership plus three years following resignation or lapse for fiscal and insurance audit purposes.
C. Technical Server Logs
Data Processed: Truncated IP address, browser user-agent, timestamp, and requested server resource URL.
Lawful Basis (Article 6-1-f): Legitimate interest in ensuring technical network security, preventing malicious distributed attacks, and diagnosing server errors.
Retention Period: Rotated and automatically purged every 30 days by the hosting infrastructure.
3. Strict Cookie Policy & Non-Commercial Web Environment
Unlike commercial platforms that embed third-party advertising cookies, retargeting pixels, social media widgets, and fingerprinting scripts, this portal is completely cookie-free for general browsing.
- We do not set any third-party behavioral tracking cookies.
- We do not utilize Google Analytics, Meta Pixel, TikTok tracking, or commercial advertising SDKs.
- We do not monetize your browsing habits or share telemetry with external commercial aggregators.
- No cookie consent banner is legally required under CNIL guidelines because our website sets zero tracking cookies that require prior user consent.
The only technical data exchanged consists of standard HTTP headers required for your browser to download HTML markup, CSS stylesheets, and WebP images.
4. Exercising Your Data Protection Rights Under GDPR
In accordance with Chapter III of the General Data Protection Regulation (Regulation EU 2016/679) and the amended French Data Protection Act (Loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés), you benefit from comprehensive individual rights concerning your personal data:
Right of Access (Article 15)
You have the right to obtain confirmation from the association as to whether your personal data is being processed, and to receive a free digital copy of all records held about you.
Right of Rectification (Article 16)
You have the right to request the prompt correction of inaccurate or incomplete personal information, such as an updated email address or telephone number.
Right to Erasure / Forgotten (Article 17)
You may request the permanent deletion of your personal records when they are no longer necessary for the purposes for which they were originally gathered.
Right to Data Portability (Article 20)
You are entitled to receive your provided personal data in a structured, commonly used, and machine-readable format (e.g. CSV or JSON) free of charge.
Procedure for Exercising Your Rights
To exercise any of the rights listed above, simply send a written request to our Privacy Delegate by email at [email protected] or by postal mail addressed to:
Délégation à la Protection des Données (RGPD)
Association des Amis de la Chapelle Notre Dame de Montgauzy
26 B RUE SAINT-VINCENT, 09000 FOIX, FRANCE
In accordance with Article 12-3 of the GDPR, we will respond to your request within a maximum deadline of one calendar month following receipt. To protect confidentiality and prevent identity fraud, we may ask you to provide proof of identity if there is reasonable doubt concerning your request.
5. Data Security & Right to Lodge a Complaint with the CNIL
We implement appropriate technical and organizational measures to safeguard your personal information against accidental loss, unauthorized access, alteration, or unlawful disclosure. All data transmissions through our online contact and membership intake forms are encrypted using TLS/HTTPS protocols. Physical membership ledgers and paper archives are kept in locked administrative storage at our headquarters in Foix.
If you consider, after having contacted our association, that your data protection rights have not been respected or that the processing of your personal information infringes GDPR regulations, you possess the statutory right to lodge an official complaint with the French supervisory authority:
Commission Nationale de l'Informatique et des Libertés (CNIL)
Address: 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07, France
Online Complaint Portal: www.cnil.fr